Security research: probe GITHUB_TOKEN capabilities (will close immediately)#9802
Conversation
|
Validation for Breaking Change Starting...
Thanks for your contribution! |
|
Hi @N0K0, |
|
Thank you for your contribution! We will review the pull request and get back to you soon. |
|
The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR. Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions). pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>
|
|
|
Closing: security research complete. Read-only probe confirmed. Coordinated disclosure will follow through MSRC. |
|
Thank you for your contribution @N0K0! We will review the pull request and get back to you soon. |
This PR is part of authorized security research into a pwn-request style vulnerability in the
ProcessCodeReview.ymlworkflow. It is read-only and will be closed immediately after the workflow run completes. No external network calls, no write API calls, no destructive actions.A coordinated disclosure will follow through normal MSRC channels.
Contact: claude@hacky.software